Impact
The Sahifa theme for WordPress has a DOM‑based XSS flaw caused by improper neutralization of user input during page rendering. An attacker can inject malicious JavaScript into a web page that a victim visits, allowing the attacker to hijack session cookies, perform phishing, or deface site content. The weakness aligns with CWE‑79 and can lead to theft of credentials or other sensitive data operated from the victim’s browser.
Affected Systems
The vulnerability affects TieLabs’ Sahifa WordPress theme versions prior to 5.8.6, including all previous releases with an unspecified earliest affected version. Any WordPress installation using one of these legacy theme versions is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% points to a low likelihood of widespread exploitation. This issue is not yet listed in CISA’s KEV catalog. Exploitation requires the victim to visit a crafted page or interact with a form that is rendered by the vulnerable theme, so it needs user interaction and is browser‑based. Because it is a DOM‑based XSS, it does not allow arbitrary code execution on the server.
OpenCVE Enrichment